Vulnerabilidades en Lenovo

394 resultados
Análisis Vexday

Com 369 CVEs catalogadas, o portfólio de vulnerabilidades da Lenovo apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em curso. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), o que sugere atenção recorrente à sanitização de dados em componentes de firmware e software proprietário. A CVE mais perigosa identificada atualmente é CVE-2022-3699, com score EPSS de 0,0428 — o maior valor observado no conjunto —, indicando probabilidade de exploração ainda relativamente baixa, mas suficiente para justificar priorização em ambientes corporativos que dependem de hardware Lenovo. As 13 vulnerabilidades surgidas nos últimos 90 dias e a presença de 4 falhas críticas reforçam a necessidade de ciclos regulares de atualização de firmware e drivers.

CVE-2022-40134MEDIUMAn information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access andEPSS 0.2%CVE-2022-40135MEDIUMAn information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and EPSS 0.2%CVE-2022-40136MEDIUMAn information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker wiEPSS 0.2%CVE-2024-8059MEDIUMIPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.EPSS 0.2%CVE-2022-48189MEDIUMAn SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privEPSS 0.2%CVE-2023-4028MEDIUMA buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker wEPSS 0.2%CVE-2023-4029MEDIUMA buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with locEPSS 0.2%CVE-2026-63427HIGHAn authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrarEPSS 0.2%CVE-2023-34419MEDIUMA buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local accEPSS 0.2%CVE-2022-4569HIGHA local privilege escalation vulnerability in the ThinkPad Hybrid USB-C with USB-A Dock Firmware Update Tool could allow an attacker with loEPSS 0.2%CVE-2022-48181MEDIUMAn ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access tEPSS 0.2%CVE-2022-48188MEDIUMA buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker withEPSS 0.2%CVE-2025-9319HIGHA potential vulnerability was reported in the Lenovo Wallpaper Client that could allow arbitrary code execution under certain conditions.EPSS 0.2%CVE-2026-8637HIGHA potential uncontrolled search path vulnerability was reported in the LanSchool Classic client application that could allow a local authentEPSS 0.2%CVE-2022-4574MEDIUM An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated prEPSS 0.2%CVE-2021-3722MEDIUMA denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow configuration files to be wEPSS 0.2%CVE-2022-3742MEDIUMA potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevatEPSS 0.2%CVE-2022-4573MEDIUM An SMI handler input validation vulnerability in the ThinkPad X1 Fold Gen 1 could allow an attacker with local access and elevated privilegEPSS 0.2%CVE-2023-4030HIGHA vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover toEPSS 0.2%CVE-2023-6044MEDIUMA privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker with physical access to impersonate LeEPSS 0.2%